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To: 

Subject: 
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Tuesday, October 03, 2017 1:34 PM 
Breaches, Data (SCA) 

Security Breach Notifications 
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Business Name: 


Foreign Business Address 1 


Philip Curtis 


Your Name: 


75 Federal Street 
Boston, MA 0211 ■ 


Contact Address 


Foreign Contact Address 




Telephone Number; 


Email Address 


Managing Partner 


tine: 


Extension: 


75 Federal Street 
Boston, MA 02110 


Other 


Owner 



















Breach Type: 


Electronic 


Dale Breach was Discovered: 

09/08/2017 

. .Number of Massachusetts Residents 
. Affected: 

0 

Person responsible for data breach.: 

Former Employee 

A'?-' A : Ay A A vAA: ; 'A ;.v' 

Tn October, 2016 we scanned H-l B petitions filed on behalf 
of two client employees in preparation for posting them to 
the resneolive enmlovees* weh nnrtals In the nrocess of 

Please give a detailed explanation of 
how the data breach occurred.: 

scanning, we inadvertently placed the filing letter for 
employee A on top of the petition filed on behalf of 
employee M (a New Jersey resident). The entire petition for 
employee M was then posted to employee A’s web portal. 

The mistake was discovered on September 8. 2017 when 
employee A reviewed the H-l B tiling and discovered that it 
was not his. We were informed via email on the evening of 
September 8. and investigated the matter on Monday 
morning, September 11. We immediately removed employee 

M’s H-1B petition from employee A’s web portal, rescanned 
employee M’s petition and placed it on bis portal. 

Please select the type of personal 
information that was included in 
the breached data.: 

Social Security Numbers = Selection(s) 

Please check ALL of the boxes that 
apply to your breach.: 

The person(s) with possession of personal information had 
authorized access = Sclection(s) 

For breaches involving paper: A 
lock or security mechanism was 
used to physically protect the data.: 

N/A 

Physical access to systems 
containing pe*sonal information 
was restricted to authorized 
personnel onlyf; 

N/a r ■ :‘; : v . . ; 

Network configuration of breached 
system: 

Closed System 

For breaches involving electronic 
systems, complete the following: 

N/A - Selection(s) 


2 








Ail Massac on setts residents aifectcc 
by the breach have been notified of 


Methmi(s) used to notify 
Massachusetts residents affected by 
the breach (check ail that apply):: 


US Mail ~ Sclcction(s) 


Date notices were first sen! to 
Massachusetts residents 
(M M/D I)/YY Y V): 


10/03/2017 


AllMassachusetts residents effected 
by the breach have been offered 
complimentary credit monitoring 
services 


Law' enforcement has been notified 
of this data breach.: 


Going forward, we will have a checklist to ensure that 
materials posted to the secure web portal belong or pertain 
only to the individual who has access to that web portal. This 
should prevent inadvertently uploading documents to the 
wrong portal. Deliberately uploading documents belonging 
to a different person would be a direct violation of the Chin 
& Curtis WISP and would be cause for dismissal. 


Please describe how your company 
responded to-the breach. Include 
what changes were made or may be 
made to prevent another similar 
breach from occurring.: 


Copyright €» 2017 Fonnstack. U,C. All rights reserved. This is a customer service einai 
Forimtack, 8604 Allisonvilie Road, Suite 300. Indianapolis. IN 46250 
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Asci, Terry (SCA) 


From: noreply@formstack.com 

Sent: Tuesday, October 03, 2017 1:34 PM 

To: Breaches, Data (SCA) 

Subject: Security Breach Notifications 
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Business: 


75 Federal Street 
Boston, MA 02110 


Foreign Business Address 


Other 


Your Name: 


Managing Partner 


75 Federal Street 
Boston* MA 02110 


Contact Address 


Foreign Contact Address 


Telephone Number 


Extension 























Breach Type: 


Electronic 


Date Breach was Discovered: 

09/08/2017 

Number of Massachusetts Residents 
Affected: 

' 0 ' ' 

Person responsible for data breach,: 

Former Employee 

• — • - • - - ; 

In October, 2016 we scanned H- l B petitions filed on behalf 
of two client employees in preparation for posting them to 

1 - ■- *. r , ' ~ ■ . .. 

the respective employees' web portals. In the process of ; 

scanning, we inadvertently placed the filing letter for 

Please give a detailed explanation of 
how the data breach occurred.: 

t/X/ / i Ull IDp VIJ UIV/ |A/UUUil IllCU VII UV^lKVilvT 

employee M (a New Jersey resident). The entire petition for 
employee M was then posted to employee A’s web portal. 

The mistake was discovered on September 8.2017 when 
employee A reviewed the Il-IB filing and discovered that it 
was not his. We were informed via email on the evening of 


oepiemnei o, anu invesugaiea me maiiei on ivionuay 
morning, September 11. Wc immediately removed employee 

M’s H-IB petition from employee A’s web portal, rescanned 
employee M’s petition and placed it on his portal. 

Please select the type of personal 
information that was included in 
the breached data.: 

Social Security Numbers ~ Selections) 

Please check ALL of the boxes that 
apply to your breach.: 

The person(s) with possession of personal information had 
authorized access = Selection^) 

For breaches involving paper: A 
lock or security mechanism was 
used to physically protect the data.: 

N/A 

V; : ^‘PIiyisiea!; : atcess to systems 

containingpersohatinforniatioii i 
; >vjs' ; re$tricted to authorizetl 
personnel©My*: 

N/A ' 

| Network configuration of breached 
system: 

Closed System 

For breaches mvolving eledrooic : 
systems, complctedhe following: 

N/A “ Selection(s) 
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bv the breach have been notified of 


Massachusetts res 


Date notices were first sent to 
Massachusetts residents 
(MM/i)I)/YVYY): 


10/03/2017 


by the breacii liave been of: 
Conifditoentai'y: credit nioui 
Services 


Law enforcement has been notified 
of this data breach.: 


Going forward, we will have a checklist to ensure that 
materials posted to the secure web portal belong or pertain 
only to the individual who has access to that web portal. Thi 
should prevent inadvertently uploading documents to the 
wrong portal. Deliberately uploading documents belonging 
to a different person would be a direct violation of the Chin 
& Curtis WISP and would be cause for dismissal. 


Please describe how your company 
responded to the breach. Include 
w hat changes were made or may be 
made to prevent another similar 
breach from occurring.: 


Copyright €> 2017 FornistacL LLC. All rights reserved. This is a customer service email 
Fonnstack, 8604 Allisonville Road, Suite 300. Indianapolis. IN 46250 


















